CVE-2024-38472
01.07.2024, 19:15
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF andmalicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.0 ≤ 𝑥 < 2.4.60 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases